Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-74
Weakness type CWE-74 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 906 | 887 | 13 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▆▅▇█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 2 · 2026-03 1 · 2026-04 0 · 2026-05 82 · 2026-06 171 · 2026-07 134 · 2026-08 229 · 2026-09 254 · 2026-10 14
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2013-2251 | 9.8 | 100.0 | KEV | Apache Struts |
| CVE-2023-22527 | 10.0 | 100.0 | KEV | Atlassian Confluence Data Center and Server |
| CVE-2019-2725 | 9.8 | 100.0 | KEV | Oracle WebLogic Server |
| CVE-2022-35914 | 9.8 | 100.0 | KEV | Teclib GLPI |
| CVE-2022-46169 | 9.8 | 100.0 | KEV | Unauthenticated Command Injection |
| CVE-2019-17558 | 7.5 | 99.9 | KEV | Apache Solr |
| CVE-2022-43769 | 8.8 | 99.9 | KEV | Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Element… |
| CVE-2025-20281 | 10.0 | 99.9 | KEV | Cisco ISE API Unauthenticated Remote Code Execution Vulnerability |
| CVE-2022-27924 | 7.5 | 99.8 | KEV | Synacor Zimbra Collaboration Suite (ZCS) |
| CVE-2020-17496 | 9.8 | 99.8 | KEV | vBulletin vBulletin |
| CVE-2019-11581 | 9.8 | 99.7 | KEV | Atlassian Jira Server and Data Center |
| CVE-2025-20337 | 10.0 | 99.3 | KEV | Cisco ISE API Unauthenticated Remote Code Execution Vulnerability |
| CVE-2020-8468 | 8.8 | 93.3 | KEV | Trend Micro Apex One, OfficeScan and Worry-Free Business Security Agents |
| CVE-2023-4548 | 2.1 | 98.3 | — | SPA-Cart eCommerce CMS GET Parameter search sql injection |
| CVE-2026-10060 | 2.1 | 92.0 | — | TRENDnet TEW-432BRP formSetRoute command injection |
| CVE-2026-10061 | 2.1 | 92.0 | — | TRENDnet TEW-432BRP formWPS command injection |
| CVE-2026-79697 | 8.6 | 91.9 | — | Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command in… |
| CVE-2026-18686 | 8.9 | 91.6 | — | GL.iNet GL-MT3000 nas-web RPC Wrapper glc nas-web.add_user command injection |
| CVE-2026-18599 | 7.3 | 91.1 | — | GL.iNet GL-MT3000 Logread Lua RPC Plugin logread logread.set_config command injection |
| CVE-2026-82595 | 2.1 | 90.9 | — | D-Link DIR-825M System Command Execution formSysCmd sub_456CF4 command injection |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| itsourcecode | 142 |
| sourcecodester | 125 |
| code-projects | 80 |
| codeastro | 41 |
| edimax | 23 |
| gl.inet | 19 |
| mathurvishal | 14 |
| trendnet | 12 |
| microsoft | 9 |
| ziroom | 9 |
| adithyayelloju | 7 |
| cisco | 7 |
| d-link | 7 |
| ibm | 7 |
| nousresearch | 7 |